
EC-CouncilNetwork Defense Essentials
Domain 2Objective 2
Security Policies and Governance NDE Practice Questions (Page 7)
Part of the Administrative and Physical Security Controls domain, which makes up ~15% of our current practice bank.
49questions here
10free pages
6concepts
Questions 31–35
- 31
A financial services firm is required by regulators to review its security policies annually. The security team is planning the review process. What should they do first?
Select an answer first - 32
A hospital is subject to HIPAA and wants to ensure that its security strategy aligns with legal obligations while also managing risks to patient data. The board asks for a framework that will guide decision-making on security investments and compliance. What should the hospital establish?
Select an answer first - 33
Which of the following is an example of a legal or regulatory requirement that can influence an organization's security policies?
Select an answer first - 34
A university's IT department has a policy that 'all systems must be configured securely.' The security team has created a document that lists the minimum password length, required encryption ciphers, and mandatory patch levels for all servers. What type of document is this?
Select an answer first - 35
A university has a policy that all research data must be backed up daily. The IT department wants to enforce this policy by setting a specific retention period and backup schedule for each storage system. What should the IT department implement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.